On-device parsing
The bank registry, the parser families and the merchant dictionary ship inside the app. No SMS is transmitted to be parsed; there is no endpoint that could receive one.
This page is the promise, in detail: what the app reads, what leaves your phone, what never does, and how that is enforced in the code rather than only in a policy. The legal version is the Privacy Policy.
A message is read on the phone, parsed on the phone, and reduced to the handful of fields a transaction needs. Only those fields travel.
Everything here is yours, visible in the app, exportable, and deleted with the account.
Not on our servers, not in the app’s database, not in a log.
The release build declares exactly these. Camera, microphone, storage, contacts and location are not requested and not declared.
The bank registry, the parser families and the merchant dictionary ship inside the app. No SMS is transmitted to be parsed; there is no endpoint that could receive one.
Migration 019 removed message bodies from the server schema and replaced them with SHA-256 digests. Dedup semantics are identical; disclosure risk from a breach is zero for message content.
The local database is SQLCipher-encrypted; the key lives in the Android Keystore. Notes are additionally encrypted with AES-256-GCM. Android’s cloud backup of app data is disabled.
Every server table is protected by Postgres row-level security keyed to the signed-in user. Balance arithmetic runs in server-side functions with a single writer, so a client cannot fabricate a balance.
Biometric lock on return to the app, and FLAG_SECURE on every financial screen so nothing reaches the screenshot pipeline or the recents thumbnail.
All traffic is HTTPS. Cleartext traffic is disabled at the platform level.
When a bank format is not recognised, you can send its shape — every digit zeroed, amounts and names replaced with placeholders — from the SMS Diagnostics screen. Nothing is sent unless you tap Send; nothing sent is linked to you.
Delete Account runs a single server function that removes your profile and cascades to every table, deletes uploaded files, then deletes the login itself and wipes the phone. There is no soft delete.
Profile → Delete Account. Server first, then the phone, in one operation. There is no retention window and no “we may keep a copy”. If you cannot open the app, the account deletion page explains how to request it.
Found something? Write to security@wealthmonk.co.in with steps to reproduce. We acknowledge reports within three working days and do not pursue researchers who act in good faith and keep user data private.
The Privacy Policy says all of this in the language a regulator expects. The app says it again, in plain words, before it asks for anything.